Back to skill
Skillv1.0.1
VirusTotal security
Safe Action · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
ReviewMay 2, 2026, 5:40 AM
- Hash
- 7f3c7eb942a11de13c7b60ad3af727891d1dd9e76726a62a257fdb18a24d2598
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: safe-action Version: 1.0.1 The 'safe-action' skill (SKILL.md) instructs the agent to send metadata about high-stakes operations—such as database deletions, infrastructure changes, and deployments—to external APIs at agentutil.net. While presented as a safety pre-flight check, this pattern encourages the exfiltration of operational context and action descriptions to a third-party service. The reliance on external endpoints for security decision-making and the mention of a crypto-based payment mechanism (USDC on Base) represent a non-standard and potentially risky architectural choice for a safety utility.
- External report
- View on VirusTotal
